CVE-2003-0466

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/08/2003
Last modified:
03/04/2025

Description

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:wu_ftpd:2.6.1-16:*:*:*:*:*:*:*
cpe:2.3:a:wuftpd:wu-ftpd:*:*:*:*:*:*:*:* 2.5.0 (including) 2.6.2 (including)
cpe:2.3:o:apple:mac_os_x:10.2.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.2.6:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:* 4.0 (including) 5.0 (including)
cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:* 1.5 (including) 1.6.1 (including)
cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* 2.0 (including) 3.3 (including)
cpe:2.3:o:sun:solaris:9.0:*:*:*:*:sparc:*:*


References to Advisories, Solutions, and Tools